The package includes a README, tests, and changelog, but its 28 runtime dependencies and install-time scripts add maintenance and upgrade complexity. The package's source and ongoing maintenance could not be verified.
38%
Total Score
50
50
50
The last release was about 7 years ago, with no releases in the past 12 months. The package had six releases overall, so current maintenance cannot be considered active.
The package declares 28 runtime dependencies and no development dependencies, creating a substantial upgrade and compatibility surface for an already stale release. The dependency list is concrete evidence of maintenance burden, not proof of a defect.
The manifest declares AGPL-3.0 and the artifact contains license files, but detected license text includes MIT rather than the declared license. The multiple license files may reflect bundled components, yet the mismatch needs clarification.
Post-install and post-update scripts run during dependency operations, increasing installation and upgrade complexity. No provided evidence shows that these scripts are unsafe or unusually broad, so this is a caution rather than a severe risk.
The artifact contains more than 10,000 files and substantial application source, consistent with a full CMS integration rather than a small library. Its size increases review and upgrade burden, but the tree also shows a complete packaged project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ~1.1 | — | — |
pear/log Version 1.13.1 | — | — |
pear/mail Version ^1.4 | — | — |
dompdf/dompdf Version 0.8.* | — | — |
marcj/topsort Version ~1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.